PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107604 Red Hat CVE debrief

A flaw in Keycloak's installation provider and client registration endpoints allows a realm administrator with the read-only view-clients role to access active primary secrets of confidential clients. This could enable impersonation and unauthorized access to service account permissions. The issue arises from insufficient access controls, potentially exposing sensitive client information. Affected deployments should prioritize verification and remediation efforts. The CVE Program and NVD provide official records of this vulnerability.

Vendor
Red Hat
Product
Red Hat Build of Keycloak
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Realm administrators, Keycloak deployment maintainers, and security teams responsible for identity management services should be aware of this vulnerability. These stakeholders need to assess their exposure, verify remediation, and ensure that appropriate compensating controls are in place. Additionally, security teams should monitor for potential unauthorized access attempts and review system logs for signs of exploitation.

Why it matters

A realm administrator with only the read-only view-clients role can access active primary secrets of confidential clients in Keycloak, potentially leading to impersonation and unauthorized access.

  • Potential impersonation of clients
  • Unauthorized access to service account permissions
  • Exposure of sensitive client secrets
  • Verification of Keycloak deployment configurations

Technical summary

A flaw in Keycloak's installation provider and client registration endpoints allows a realm administrator with the read-only view-clients role to access active primary secrets of confidential clients. This issue arises from a lack of proper authorization checks, enabling potential impersonation and unauthorized access to service account permissions. The vulnerability is considered medium severity with a CVSS score of 4.9. Affected systems should apply patches or mitigations promptly to prevent exploitation. The vulnerability affects Keycloak's client registration and installation provider endpoints.

Defensive priority

Realm administrators and Keycloak deployment maintainers should assess exposure and verify remediation.

Recommended defensive actions

  • Verify Keycloak installation provider and client registration endpoint configurations.
  • Restrict access to sensitive client secrets.
  • Monitor for unauthorized access attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE Program and NVD provide official records of this vulnerability. Red Hat provides additional details through their security advisory. Evidence is based on official CVE and NVD documentation, as well as Red Hat's security advisory. The vulnerability has been publicly disclosed and verified by multiple sources. No additional information is available on potential exploits or attacks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107604 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107604

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107604 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107604

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.